Vulnerability Bulletins

IBM Security Bulletin: IBM SmartCloud Orchestrator - Keystone privilege escalation through trust chained delegation (CVE-2014-3476)

   
Affected software IBM
 
By creating a delegation from a trust or OAuth token, a trustee may abuse the identity impersonation against keystone and circumvent the enforced scope, resulting in potential elevated privileges to any of the trustors projects and or roles. All Keystone deployments configured to enable trusts are affected, which has been the default since Grizzly. CVE(s): CVE-2014-3476 Affected product(s) and affected version(s): SmartCloud Orchestrator 2.3, SmartCloud Orchestrator 2.3 FixPack1 up to iFix

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_smartcloud_orchestrator_keystone_privilege_escalation_through_trust_chained_delegation_cve_2014_3476?lang=en_us